Q: Engineers frequently bypass Terraform during production emergencies, modifying Security Groups, opening ports, and changing IAM roles directly in the AWS/Azure console. Over time, actual cloud state diverges dangerously from Git, causing future Terraform plans to destroy resources or overwrite security patches. How do you design an automated, continuous IaC drift detection and reconciliation platform?
Architectural design for a continuous Infrastructure as Code (IaC) governance engine detecting out-of-band manual cloud modifications, alerting via Slack, and automatically reconciling state via GitOps.
Want to master this scenario in a live sandbox? The Linux Foundation's FinOps Certified Practitioner (FOCP) Program covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Deploy Continuous Drift Scanning Daemons (Driftctl / Terraform Plan)
Scan cloud resources continuously against Terraform state files:
- Automated Scanner: Deployed a Kubernetes CronJob running Driftctl /
terraform plan -detailed-exitcodeevery 4 hours across 60 cloud accounts. - Resource Coverage: Scans security groups, IAM roles, route tables, S3 bucket policies, and RDS parameters against remote state stored in S3/DynamoDB.
Classify Drift Severity & Filter Benign Ephemeral Changes
Distinguish between dangerous security regressions and harmless cloud tags:
- Severity Tiers: Classified drift into Critical (security group opened to 0.0.0.0/0, IAM privilege escalation) and Low (auto-scaling tag changes, modified timestamps).
- Ignore Rules: Configured driftfilter rules ignoring cloud provider auto-generated metadata (e.g. AWS default KMS aliases).
Correlate Drift with CloudTrail to Identify Who Made the Change
Provide immediate accountability by attaching user attribution to alerts:
- CloudTrail Correlation: Scanner queries CloudTrail event logs to identify the exact human engineer or automation role that made the manual console modification.
- Interactive Slack Card: Dispatches alert to
#cloud-drift-sec: '🚨 Security Drift Detected in prod-vpc: Port 22 opened by user john.doe@company.com via AWS Console 23 mins ago. [Reconcile Git State] or [Adopt into Code]'.
Automate Self-Healing Reconciliation via GitOps PR Generation
Close the loop by bringing infrastructure back to declared Git code:
- Auto-Revert Mode: For Critical security resources (firewalls/IAM), automated pipeline runs
terraform applyto immediately revert the manual change within 15 minutes. - Auto-PR Mode: For approved resource additions, automation automatically generates a GitHub pull request with the required HCL code to adopt the resource into git.
- Drift Free Posture: Achieved 99.8% code-to-cloud parity across 14,000 cloud infrastructure resources.
- Schedule continuous automated Driftctl and terraform plan scans across all cloud accounts.
- Correlate detected drift with CloudTrail to identify the responsible engineer and timestamp.
- Auto-revert unauthorized security changes (firewalls/IAM) within 15 minutes.
- Generate automated GitHub PRs to adopt legitimate out-of-band changes into code.